Xunjin Zheng

dblp:358/8889 · DBLP profile ↗
← Back
2ranked-venue papers
0as first author
2since 2021 · last 2024
0009-0002-8146-4861ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 2 · 2 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Software engineering, system software, and programming languages
2 papers
Program synthesis and code generation · 61% Program analysis · 30% Programming languages and type systems · 9%
Network and information security
1 paper
Systems and software security · 100%
Artificial intelligence
1 paper
Efficient and distributed learning · 100%

Topics — the 6 heaviest of 6, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Systems and software security › software vulnerability
deserialization vulnerability
0.812024
GrayDuck: The Sword of Damocles for Duck Typing in Dynamic Language Deserialization · ASE 2024
Program synthesis and code generation
code completion
0.812024
RepoGenix: Dual Context-Aided Repository-Level Code Completion with Language Models · ASE 2024
Program synthesis and code generation › code completion
repository-level code completion
0.812024
RepoGenix: Dual Context-Aided Repository-Level Code Completion with Language Models · ASE 2024
Program analysis
static analysis
0.812024
GrayDuck: The Sword of Damocles for Duck Typing in Dynamic Language Deserialization · ASE 2024
Machine learning › Efficient and distributed learning › inference efficiency
LLM inference optimization
0.212024
RepoGenix: Dual Context-Aided Repository-Level Code Completion with Language Models · ASE 2024
Programming languages and type systems › language semantics
dynamic semantics
0.212024
GrayDuck: The Sword of Damocles for Duck Typing in Dynamic Language Deserialization · ASE 2024

Methods — techniques the papers use, named apart from their topics

static analysis · 1.5language model · 1.5context-aware selection · 1.5class relation graph · 1.5
YearPublicationVenuePosition
2024 RepoGenix: Dual Context-Aided Repository-Level Code Completion with Language Models
abstract
The success of language models in code assistance has spurred the proposal of repository-level code completion as a means to enhance prediction accuracy, utilizing the context from the entire codebase. However, this comprehensive context comes at a cost: while it enhances model performance, it also increases inference latency. This balance between improved accuracy and computational efficiency poses a significant challenge in real-world applications. We present RepoGenix, a solution that enhances repository-level code completion without increased latency. RepoGenix combines analogous context and relevant context, using Context-Aware Selection technology to efficiently compress these contexts into limited-size prompts. Our experiments on CrossCodeEval demonstrate that RepoGenix not only achieves a substantial 48.41% reduction in inference time, but also yields improvement in performance compared to baseline methods. We have successfully implemented and tested RepoGenix within AntGroup's development environments. This approach is being extended to multiple programming languages and will be open-sourced, aiming to enhance code completion efficiency for the broader developer community.
Xiaoheng Xie, Gehao Zhang, Xunjin Zheng, Peng Di, Wei Jiang 0041, Chengpeng Wang 0001, Gang Fan
ASE4
2024 GrayDuck: The Sword of Damocles for Duck Typing in Dynamic Language Deserialization
abstract
Duck typing is a flexible programming style in dynamic languages, enabling the achievement of complex behaviors using less code. The use of duck typing is currently widespread; however, the question is whether its use in code is truly safe. In fact, improper use of duck typing may introduce unexpected security threats. In this paper, we reveal another side of duck typing, showing how it can exacerbate the impact of deserialization vulnerabilities and expand the range of attack options for attackers. We present three cases of duck typing misuse and theoretically demonstrate how such misuse can expand the attack surface of deserialization vulnerabilities. Additionally, we design a static analysis tool, GrayDuck, to construct a Class Relation Graph (CRG) that clearly delineates the range of classes accessible through each deserialization operation and identify instances of duck typing misuse along with the associated attack surfaces so that to assess the potential harm. We utilized this tool to scan 5 Python programs known to have real deserialization vulnerabilities, detecting 7 issues of deserialized object duck typing misuse and calculating the corresponding expansions of the attack surfaces.
Xunjin Zheng, Cai Fu, Xiaoheng Xie, Peng Di
ASE2